Known Vulnerabilities for Leantime by Na
Listed below are 4 of the newest known vulnerabilities associated with "Leantime" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59713 json | Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without vali... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-59712 json | Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retri... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-15510 json | A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The ma... | Not Provided | 2026-07-12 | 2026-07-13 |
| CVE-2026-15509 json | A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC ... | Not Provided | 2026-07-12 | 2026-07-15 |